CVE-2026-103040
published 2026-09-29CVE-2026-103040: LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| modeltc | lightllm | <= 1.2.0 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ModelTC LightLLM up to 1.2.0 Router Profiler Service deserialization
vuldb·2026-09-30·CVSS 9.8
CVE-2026-103040 [CRITICAL] ModelTC LightLLM up to 1.2.0 Router Profiler Service deserialization
A vulnerability identified as critical has been detected in ModelTC LightLLM up to 1.2.0. Affected by this issue is some unknown functionality of the component Router Profiler Service. Performing a manipulation results in deserialization.
This vulnerability is cataloged as CVE-2026-103040. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag.
ghsa_unreviewed·2026-09-30
CVE-2026-103040 [CRITICAL] CWE-502 LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag.
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ModelTC/LightLLMhttps://github.com/ModelTC/LightLLM/issues/1597https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L32-L34https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L46-L50https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-router-profiler-rpyc-servicehttps://github.com/ModelTC/LightLLM/issues/1597
2026-09-29
Published